Vulnerabilidades en wolfSSL

94 resultados
Análisis Vexday

O histórico de vulnerabilidades do wolfSSL acumula 91 CVEs catalogadas, com uma concentração expressiva de 55 entradas surgidas nos últimos 90 dias, o que indica um período recente de escrutínio intensificado ou atualização de catalogação. A taxa de exploração ativa está abaixo da média geral do catálogo KEV, com nenhuma CVE confirmada em uso por agentes de ameaça no momento, embora a CVE-2017-13099 — associada à falha de tipo mais recorrente na biblioteca, CWE-295 (validação inadequada de certificados) — apresente o maior score EPSS observado (0,2492), sugerindo probabilidade não desprezível de exploração futura. As 7 CVEs de severidade crítica e a existência de prova de conceito pública para ao menos uma vulnerabilidade reforçam a necessidade de atenção contínua ao processo de atualização em ambientes que dependem dessa biblioteca TLS/SSL embarcada. Equipes de segurança devem priorizar a revisão de versões em uso, especialmente em contextos de IoT e sistemas embarcados onde ciclos de patching tendem a ser mais lentos.

CVE-2026-5187LOWHeap Out-of-Bounds Write in DecodeObjectId() in wolfSSLEPSS 0.3%CVE-2026-3579LOWNon-constant time multiplication subroutine __muldi3 on RISC-V RV32IEPSS 0.3%CVE-2026-5446MEDIUMwolfSSL ARIA-GCM TLS 1.2/DTLS 1.2 GCM nonce reuseEPSS 0.3%CVE-2026-10097HIGHML-KEM-1024 x64 AVX2 incomplete cipher text comparison enables IND-CCA2 break and static private-key recoveryEPSS 0.3%CVE-2026-3547HIGHwolfSSL: out-of-bounds read (DoS) in ALPN parsing due to incomplete validationEPSS 0.3%CVE-2025-11932LOWTiming Side-Channel in PSK Binder VerificationEPSS 0.3%CVE-2026-7511MEDIUMPKCS7_verify signer confusion allows forged signatures to be acceptedEPSS 0.3%CVE-2026-1005LOWInteger underflow leads to out-of-bounds access in sniffer AES-GCM/CCM/ARIA-GCM decrypt pathEPSS 0.3%CVE-2026-6291MEDIUMBleichenbacher padding oracle in PKCS#7 KTRI RSA PKCS#1 v1.5 decryptionEPSS 0.2%CVE-2025-7395CRITICALDomain Name Validation Bypass with Apple Native Certificate ValidationEPSS 0.2%CVE-2026-55962MEDIUMTLS 1.3 post-handshake authentication: server accepts Finished without client Certificate/CertificateVerifyEPSS 0.2%CVE-2026-11310HIGHX.509 trust-chain bypass in wolfSSL_X509_verify_cert() via untrusted intermediate anchoringEPSS 0.2%CVE-2026-55960HIGHUn-negotiated Raw Public Key (RFC 7250) accepted in place of X.509, bypassing chain validationEPSS 0.2%CVE-2026-11999HIGHX.509 trust-chain bypass via path-depth exhaustion in wolfSSL_X509_verify_cert()EPSS 0.2%CVE-2026-5772LOWMatchDomainName 1-Byte Stack Buffer Over-Read in Hostname ValidationEPSS 0.2%CVE-2026-5778LOWInteger underflow leads to out-of-bounds access in sniffer ChaCha decrypt path.EPSS 0.2%CVE-2026-5447MEDIUMHeap buffer overflow in CertFromX509() via AuthorityKeyIdentifierEPSS 0.2%CVE-2026-6329MEDIUMPKCS#12 MAC verification uses attacker-controlled comparison lengthEPSS 0.2%CVE-2025-11935MEDIUMForward Secrecy Violation in WolfSSL TLS 1.3EPSS 0.2%CVE-2026-5460MEDIUMHeap Use-After-Free in PQC Hybrid KeyShare Error Cleanup in wolfSSL TLS 1.3EPSS 0.2%